9.8
CVSSv3

CVE-2021-40323

Published: 04/10/2021 Updated: 12/10/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cobbler prior to 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cobbler project cobbler

Vendor Advisories

A flaw was found in cobbler This flaw lies in the generate_script RPC method, which accepts unsanitized parameters This flaw allows an attacker to read arbitrary files on the system as root Further, the attacker could gain arbitrary code execution using template injection against the default Cheetah template engine, leading to the exposure of se ...